PT-2026-56852 · Pypi · Pymonocypher

CVE-2026-53720

·

Published

2026-07-09

·

Updated

2026-09-03

CVSS v4.0

5.1

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pymonocypher versions prior to 4.0.2.8
Description The argon2i 32() function fails to verify the size of the nb blocks buffer. If the provided buffer is smaller than required by the API contract, the function may write beyond the buffer boundaries, potentially leading to heap corruption.
Recommendations Update to version 4.0.2.8. As a temporary workaround, ensure a correctly sized nb blocks buffer is provided.

Exploit

Fix

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53720
GHSA-8F95-V3JQ-CJ86
PYSEC-2026-3000

Affected Products

Pymonocypher